perf/core: Change the default paranoia level to 2
authorAndy Lutomirski <luto@kernel.org>
Mon, 9 May 2016 22:48:51 +0000 (15:48 -0700)
committerLinus Torvalds <torvalds@linux-foundation.org>
Tue, 10 May 2016 00:57:12 +0000 (17:57 -0700)
commit0161028b7c8aebef64194d3d73e43bc3b53b5c66
tree6e7ffbfc92345548730fb7b33f8168760f99fa28
parent5c56b563b4486281bff80658194f0d1da6feba67
perf/core: Change the default paranoia level to 2

Allowing unprivileged kernel profiling lets any user dump follow kernel
control flow and dump kernel registers.  This most likely allows trivial
kASLR bypassing, and it may allow other mischief as well.  (Off the top
of my head, the PERF_SAMPLE_REGS_INTR output during /dev/urandom reads
could be quite interesting.)

Signed-off-by: Andy Lutomirski <luto@kernel.org>
Acked-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Documentation/sysctl/kernel.txt
kernel/events/core.c